🛡 Gemini hacked three companies during a test
In May, Irregular tested Gemini's cyber capabilities with internet access: for one company, the model guessed passwords through brute force, and for two others, it found credentials in a public repository. At the end of July, Irregular notified the labs: the issues have been resolved.
🌍 This is the first known "breakout" by Google's AI, but similar incidents during tests via Irregular have been acknowledged by Meta, Anthropic, and OpenAI. An agent is given the internet without isolation — and the test turns into a real attack.
👤 The essence is simpler than the headline: weak passwords and leaked credentials were exploited, not a "hacker-style" hack. Do not store secrets in public repositories and do not give agents internet access without a sandbox.
Source 1: https://economictimes.indiatimes.com/tech/technology/gemini-hacked-three-companies-in-first-known-breakout-by-googles-ai-wsj/articleshow/134346436.cms Source 2: https://tech.yahoo.com/ai/gemini/articles/gemini-hacked-three-companies-first-222515088.html
